Plaxo's servers used to access Google Accounts, and their cryptic response
blog.plaxo.com
blog.plaxo.com
Who has been compromised?
What is the exposure?
Password changing is recommended, but why?
If they were using OAUTH, why is it necessary to change passwords? (And what about users of 2 step authentication?)